Gravityforms

Gravity Forms

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 02.05.2026 05:29:30
  • Zuletzt bearbeitet 05.05.2026 19:16:18

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping in the SingleProduct field when used inside a...

  • EPSS 0.25%
  • Veröffentlicht 02.05.2026 05:29:29
  • Zuletzt bearbeitet 05.05.2026 19:16:18

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escaping of Product Option field values. The vulnerability exists because th...

  • EPSS 0.25%
  • Veröffentlicht 02.05.2026 05:29:29
  • Zuletzt bearbeitet 05.05.2026 19:16:18

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping on Hidden Product field values when used inside Repeater fiel...

  • EPSS 0.23%
  • Veröffentlicht 02.05.2026 05:29:28
  • Zuletzt bearbeitet 05.05.2026 19:16:18

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping of Calculation Product field product names wh...

  • EPSS 0.24%
  • Veröffentlicht 02.05.2026 05:29:28
  • Zuletzt bearbeitet 05.05.2026 19:16:18

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2.10.0. This is due to a flawed state validation mechanism that fails open when input is sanitized by ...

  • EPSS 0.29%
  • Veröffentlicht 07.04.2026 23:25:28
  • Zuletzt bearbeitet 27.04.2026 19:04:22

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Type' sub-field (`input_<id>.4`) in all versions up to, and including, 2.9.30. This is due to the `get_value_entry_detail()` method ...

  • EPSS 0.36%
  • Veröffentlicht 07.04.2026 23:25:27
  • Zuletzt bearbeitet 27.04.2026 19:04:22

The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `gform_get_config` AJAX action in all versions up to, and including, 2.9.30. This is due to the `GFCommon::send_json()` method ...

  • EPSS 0.2%
  • Veröffentlicht 11.03.2026 09:25:43
  • Zuletzt bearbeitet 22.04.2026 21:27:27

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.28.1. This is due to a compound failure involving missing authorization on the `create_from_template` AJAX endpoint (allowin...

  • EPSS 0.59%
  • Veröffentlicht 18.11.2025 03:27:07
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mechanism in all versions up to, and including, 2.9.21.1. This is due to the extension blacklist not inclu...

  • EPSS 0.66%
  • Veröffentlicht 07.11.2025 04:28:53
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to...